Chapter 4Securing Blockchain Applications: Practical Examples
For the things we have to learn before we can do them, we learn by doing them.
—Aristotle
4.1 Introduction
This chapter introduces practical examples to help you get started on your blockchain security practitioner journey. You’ll focus on two key aspects: smart contract auditing and building a decentralized application (dApp) on Amazon Web Services (AWS) by leveraging AWS-managed blockchain [48], with the explicit goal of preparing both for threat modeling and security code reviews.
The code vulnerability auditing example targets specific code areas where blockchain vulnerabilities commonly occur. Previous chapters outlined security risks and best practices – now, we shift to real-world code examples that may contain flaws. You’ll examine blockchain node software, wallet software, and dApps, with a special emphasis on smart contract code. Each component presents unique challenges but requires detailed code reviews to detect bugs, design flaws, and misconfigurations.
Auditing this code is essential for ensuring system integrity, preventing unauthorized access, and reducing the risk of financial or reputational damage. We’ll connect known vulnerabilities from earlier chapters to actual code samples, demonstrating how to apply security principles in practice. The goal is to equip developers, security engineers, and architects with practical techniques to audit and strengthen blockchain implementations.
In the dApp-building ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access